Description
Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP Rentals: from n/a before 3.16.0.
This issue affects WP Rentals: from n/a before 3.16.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the WordPress WP Rentals Theme to the latest available version (at least 3.16.0).
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 04 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0. | |
| Title | WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR) vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-09-04T08:45:06.734Z
Reserved: 2026-02-19T09:52:32.857Z
Link: CVE-2026-27432
No data.
Status : Received
Published: 2026-09-04T09:17:10.543
Modified: 2026-09-04T09:17:10.543
Link: CVE-2026-27432
No data.
OpenCVE Enrichment
No data.
Weaknesses